logo

Microsoft issues emergency update for macOS and Linux ASP.NET threat

ID: 33bc92d9-a73f-583d-b21b-04101cf6c9b8

STIX ID: report--33bc92d9-a73f-583d-b21b-04101cf6c9b8

Feed Name: Security - Ars Technica

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-05-22

Author: Dan Goodin

...
...

Microsoft issued an emergency patch for ASP.NET Core to address CVE-2026-40372, a high-severity flaw in Microsoft.AspNetCore.DataProtection (v10.0.0–10.0.6) that can let unauthenticated attackers forge authentication payloads during HMAC validation and gain SYSTEM-level privileges on Linux and macOS applications; tokens or credentials created during the vulnerable period remain valid after updating unless the DataProtection key ring is rotated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.